Hello.
I needed to monitor what was sent from a service account
serviceSMTP@domain.tld
This account is used by some devices for backup and error reporting and has very restrictive throttle parameters
The device authenticates with serviceSMTP@domain.tld then sets a from and a to
To my amazement I saw that among the events it is not possible to filter by authentication account limiting the possibility of control.
Apart from the specific case described, it is not uncommon for a user to authenticate with an account and then send by setting a different from.
Even if we archive the messages there is no evidence of this situation.
So in fact it becomes complex to check what a certain authenticated user sends in case of need
Sabatino Traini
Chief Information Officer